The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted request
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/0c96a128-4473-41f5-82ce-94bba33ca4a3/ | third party advisory exploit technical description vdb entry |
https://www.relevanssi.com/release-notes/premium-2-25-free-4-22-release-notes/ | patch |